Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • Nepal protests
  • Nepal Protests Live
  • Vice-presidential elections
  • iPhone 17
  • IND vs PAK cricket
  • Israel-Hamas war
fp-logo
'CISOs Should Know How To Make Risk Mgmt Profitable'
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
  • Home
  • Business
  • Biztech
  • 'CISOs Should Know How To Make Risk Mgmt Profitable'

'CISOs Should Know How To Make Risk Mgmt Profitable'

FP Archives • February 2, 2017, 22:27:32 IST
Whatsapp Facebook Twitter

Vishal Salvi, CISO-HDFC Bank, talks about the strategy a CISO should adopt to generate revenues from the risk management roadmap.

Advertisement
Subscribe Join Us
Add as a preferred source on Google
On
Google
Prefer
Firstpost
'CISOs Should Know How To Make Risk Mgmt Profitable'

Risk management and information security are highly debated topics in CIO and CISO circles. Information risk management is often weighed only from a cost perspective; however; the business growth and reputation angle plays a much larger role in this scenario. Biztech2.com spoke to Vishal Salvi, CISO-HDFC Bank, on the strategy a CISO should adopt to generate revenues from the risk management roadmap.

How can a CISO drive business growth by ensuring better risk management practices?

STORY CONTINUES BELOW THIS AD

The purpose of the Information Security & Risk Management function is to allow business to run with minimal risks. The customer has a choice and security is already becoming a key differentiator. Especially in the banking business when we deal with our customer’s money, we need to ensure that the customer’s privacy and money are both safeguarded.

More from Biztech
Future Group - Reliance Retail Deal approved by CCI Future Group - Reliance Retail Deal approved by CCI RBI ban on cryptocurrencies takes effect; prohibition could force investors to tap the black market RBI ban on cryptocurrencies takes effect; prohibition could force investors to tap the black market

The second important aspect is business confidence; a robust information security platform provides the thrust to business to offer different types and flavours of products to customers only because you are assured of security controls.

To give you an analogy, a car with a better break system would go faster than others and that’s why F1 cars have the strongest breaks. Therefore, for business to grow faster, you need to have a robust risk management process in place.

What challenges does a CISO face in the above process?

The inherent characteristics of information security make it such that it is visible only when it is not working and invisible when it is working. So how do you prove the derived value? I, therefore, feel that CISOs have an important role to play to ensure that they get their risk assessment spot on, as we are investing to assure that bad things do not occur and it could either be because of the good controls being implemented or you were plain lucky and not a target.

Secondly, business integration and understanding is a key for success. As the security function has evolved through IT, there is still a tendency to be more technology focused and less business focused. This needs to change if we want to see information security help business growth.

Awareness and consistent understanding of one’s role pertaining to information security is also a significant challenge. If people knew and practiced their part, the number of security issues would be far lesser.

STORY CONTINUES BELOW THIS AD

What should the CISO do to overcome these challenges?

The primary role of the CISO is that of a change agent, thus, building a culture of information security and making people realise and experience the value created by information security lies in the hands of the CISO. He should regularly brief and inform the business on the potential risks averted due to the security solutions in place. This includes quantifiable inputs and examples like how many viruses, malware etc were stopped in the past month. What would have been the potential downtime if they had hit the system? Communication with the business is important at all times. A few pointers for success are as follows:

1. Build a holistic framework with a clear vision on what are the strategic as well as tactical goals.

2. Be flexible and adaptable; do not expect overnight changes.

3. Retain your technology base [traditional stronghold] but engage with business more.

STORY CONTINUES BELOW THIS AD

4. Align compliance requirements to your strategy and vice versa.

5. Build a comprehensive and continuous awareness strategy.

6. Collaborate with industry peers and share ideas and concepts.

7. Measure success and share success stories.

Can you give us some examples of the risk management initiatives undertaken at HDFC Bank?

As mentioned above, the aligning of risk management and compliance needs is the key. At HDFC Bank, all the regulation and compliance requirements have been consolidated into one single information security policy document, which has links to the different frameworks/ regulations. With this arrangement, users have to refer to only one single policy document and hence, it becomes simple as well as cost effective to manage and implement the controls.

Robust risk management processes and metrics are important to understand what is happening and which are the areas that need improvement. The CISO’s approach needs to shift from threat & vulnerability assessment to holistic risk management.

STORY CONTINUES BELOW THIS AD
Tags
HDFC Bank CIO risk management Information security Vishal Salvi CISO
End of Article
Written by FP Archives

see more

Latest News
Find us on YouTube
Subscribe
End of Article

Top Stories

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Who is CP Radhakrishnan, India's next vice-president?

Who is CP Radhakrishnan, India's next vice-president?

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Who is CP Radhakrishnan, India's next vice-president?

Who is CP Radhakrishnan, India's next vice-president?

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Top Shows

Vantage Firstpost America Firstpost Africa First Sports
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV